浏览器自检与伪装 -- 选择出口,用 BrowserScan、CreepJS、FingerprintJS 与真实 Cloudflare 验证页给浏览器打分(0–100,附扣分原因);浏览器可伪装为 Windows / macOS / Linux,可上传自己的 Windows / Mac 字体,时区跟随出口 IP 所在城市
If Bemby saves you time, please consider giving it a star on GitHub. It helps others find the project and keeps development going.
A self-hosted automation tool for managing daily Telegram bot check-ins (签到) and Emby video-watch sessions. Includes a web admin portal for managing multiple accounts and jobs.
The open-source build stopped at v1.0.0 (the :latest image, August 2026). Everything since is in Pro only (the :pro image). The main additions are below; the changelog has the details.
Web and Mini App automation
Many new page steps -- type on the keyboard, press a key (Enter / Ctrl+Enter), press and hold (also at an offset), drag a slider or puzzle piece, pick a dropdown option, go to a URL and back, scroll to an element, read text, pick or collect elements, run a script on the page
Flow control -- if / else branches, repeat a number of times, for each value in a list, end the job early as a success or failure, hand the job over to another template
Variables and AI input -- set variables (random placeholders included), have the AI write into a field, send a notification mid-run
Email and 2FA -- read a verification code or link from email, take an address from a mailbox pool, msOauth2api mailbox sign-in, capture a two-factor secret and work out its authenticator code (TOTP)
Passkeys -- register a passkey on a virtual security key, save it and sign in with it later, no hardware needed
Picture captchas -- the AI solves hCaptcha-style image grids and can click several positions at once; Cloudflare Turnstile inside Mini Apps; pages inside iframes
Watch and drive the browser -- follow a job's browser live over VNC, or open one by hand; manage, rename and clear browser profiles, or run without one
Mini Apps on the reply keyboard -- the app buttons above the composer open too, and their sendData result is passed to the bot as the official client does
Browser self-test and persona -- pick an exit and score the browser on BrowserScan, CreepJS, FingerprintJS and real Cloudflare challenge pages (0-100, with what cost points); the browser can claim Windows, macOS or Linux, takes your own Windows / Mac fonts, and keeps the exit IP city's timezone
Data
Data store -- folders of records that outlive a run (accounts a signup made, invite codes), read in any field as {data.folder.key} and written or deleted from a job; sort, filter, import and export (plain text too)
Loop over a data folder -- one round per record, skipping records already done, so a rerun carries on where the last stopped
Telegram accounts
Session (card) accounts -- bulk-import bought session accounts, check they are alive first, then take ownership of them in bulk
Bulk Set Privacy and Bulk Extract Messages (pull text out of one chat by keyword and regex, optionally into the data store)
Bulk profile extras -- random avatars (an avatar pool you can stock ahead, zip upload included) and usernames (@handle)
Share phone number, account search and filters, phone number validation, a Telegram avatar and user ID column, low-limited spam status, manual reconnect
Messenger
Channel DMs, polls and quizzes (vote and see the results), @-mentions of group members who have no username, member search in groups, group service messages, reply previews with jump-to, stickers, and each account's folder remembered
Telegram layer 229, so a bot's rich page messages render instead of showing blank
Jobs and scheduling
One-time jobs, run-every-X-days for every job type, job icons, filters on the jobs list
More flexible check-in -- match buttons by text, several keywords, a button from the pinned message first, the check-in button from the last message's keyword
Group join verification -- the AI picks the verification button (with a custom hint), and a check posed as a quiz poll is answered too
Bulk jobs -- run in the background, can be paused and skipped, with an adjustable gap; account filters when creating jobs from a template
Per-job proxy override, and template editing straight from the jobs list
A sturdier scheduler -- planned times survive an upgrade, hung runs are reclaimed, runs missed today are caught up today, and the simultaneous run cap is a setting
Mark a job successful or failed by hand -- correct the latest run's verdict or record the work as done by hand, and the next run is planned from that
Proxies
Node subscriptions (VLESS / VMess / Trojan / Shadowsocks, with the Xray core), a global proxy for censored networks, random proxy pools, proxy health checks and testing, auto refresh
Emby Watch
More servers (including play-session gateways), ignore an invalid SSL certificate, and a proxy of its own for the watch job
System
Light / dark theme, update check, system log in Settings, system reboot, Telegram connections panel with a connection cap, and a way back in from a forgotten password
Run screenshots kept out of the database (527MB to 35MB on a real install), and a panel whose first load is about 70% smaller
Images are published to both Docker Hub and the GitHub Container Registry (GHCR) with identical contents; use either liveinaus/bemby:pro or ghcr.io/liveinaus/bemby:pro.
Image tags: :pro is the stable Pro build (recommended); :dev is the development build; :beta is the beta; :latest is the last open-source release, v1.0.0, and no longer moves. To move from :latest, change the image to liveinaus/bemby:pro; the data directory carries over as it is.
JWT_SECRET is required and must not be a publicly known placeholder (e.g. change-me-in-production), or the app refuses to start. Generate one with openssl rand -hex 32.
Defaults: port 3000, database at /app/data/bemby.db, timezone UTC. To set a timezone add -e TZ=Australia/Sydney.